helianthus | 21.04.2014 22:59 | Wow...die Hilfsbereitschaft ging ja fix :-)
Also Schritt 1 hat ergeben:
FRST.txt:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-04-2014 02
Ran by Arne (administrator) on ARNE_WALTHER_PC on 21-04-2014 23:52:35
Running from C:\Users\Arne\Desktop\Trojanerboard
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe
(Nalpeiron Ltd.) C:\WINDOWS\SysWOW64\NLSSRV32.EXE
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe
(Validity Sensors, Inc.) C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe
(Validity Sensors, Inc.) C:\WINDOWS\System32\valWBFPolicyService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\QuickSnipService\QuickSnipService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe
() C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Lenovo) C:\Program Files\lenovo\QuickSnipService\QuickSnipInput.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tposd.exe
() C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Validity Sensors, Inc.) C:\Program Files\Lenovo Fingerprint Reader\SwipeMonitor.exe
(Microsoft Corporation) C:\WINDOWS\system32\wwahost.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Realtek Semiconductor Corp.) C:\Windows\RtsCM64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(SMART Technologies ULC) C:\Program Files (x86)\SMART Technologies\Education Software\FloatingTools.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTNotification.exe
(Lenovo Corporation) C:\Program Files\Lenovo\Communications Utility\vcamsvchlpr.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTTrayIcon.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe
(Joyent, Inc) C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\SBWDKService.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInk.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\Office\SMARTInk-SBSDKProxy.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInkPrivilegedAccess.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [LenovoOptMouseUpdate] => C:\Program Files\Lenovo\HOTKEY\extapsup.exe [250976 2012-09-01] (Lenovo Group Limited)
HKLM\...\Run: [RtsCM] => C:\WINDOWS\RTSCM64.EXE [140872 2013-03-21] (Realtek Semiconductor Corp.)
HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [11733888 2012-12-03] (Motorola Solutions, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2986224 2013-07-09] (Synaptics Incorporated)
HKLM\...\Run: [TpShocks] => C:\WINDOWS\system32\TpShocks.exe [382248 2013-02-12] (Lenovo.)
HKLM\...\Run: [LnvMobHotspotClient] => C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe [937976 2013-04-08] (Lenovo)
HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [594936 2013-02-28] (Lenovo Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-03-07] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SMART Floating Tools] => C:\Program Files (x86)\SMART Technologies\Education Software\FloatingTools.exe [9024304 2013-11-20] (SMART Technologies ULC)
HKLM-x32\...\Run: [SMARTNotification] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTNotification.exe [204592 2013-11-22] (SMART Technologies)
HKLM-x32\...\Run: [SMART Tray Tools] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTTrayIcon.exe [743728 2013-11-22] (SMART Technologies)
HKLM-x32\...\Run: [SMART Board Service] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTBoardService.exe [1933104 2013-11-22] (SMART Technologies)
HKLM-x32\...\Run: [sbsdk-server] => C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\NodeLauncher.exe [62768 2013-08-22] (SMART Technologies)
HKLM-x32\...\Run: [SMART Ink] => C:\Program Files (x86)\SMART Technologies\Education Software\SMARTInk.exe [147248 2013-10-31] (SMART Technologies)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2011-03-09] (CyberLink)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2012-06-14] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [234000 2012-06-14] (CyberLink Corp.)
HKLM-x32\...\Run: [LGODDFU] => C:\Program Files (x86)\lg_fwupdate\lgfw.exe [27760 2012-07-12] (Bitleader)
HKLM-x32\...\Run: [Lenovo App Shop] => "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [180304 2014-04-01] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-25] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3376538931-3444952228-2368489750-1001\...\MountPoints2: {b7795a28-8eac-11e3-be7a-606c66a14810} - "D:\iStudio.exe"
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/thinkpad
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {D79C94F7-03FF-4BB4-A93E-9F01332E1119} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM - {02D81F03-F601-4871-8215-CA33C8C37044} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LNJB
SearchScopes: HKLM - {D79C94F7-03FF-4BB4-A93E-9F01332E1119} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM-x32 - {02D81F03-F601-4871-8215-CA33C8C37044} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LNJB
SearchScopes: HKCU - {02D81F03-F601-4871-8215-CA33C8C37044} URL =
SearchScopes: HKCU - {D79C94F7-03FF-4BB4-A93E-9F01332E1119} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: SMART Notebook Download Utility - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files (x86)\SMART Technologies\Education Software\NotebookPlugin.dll (SMART Technologies ULC.)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\u2cdbf3d.default
FF DefaultSearchEngine: SuchMaschine
FF SearchEngineOrder.1: SuchMaschine
FF SelectedSearchEngine: SuchMaschine
FF Homepage: about:home
FF Keyword.URL: hxxp://www.sm.de/?q=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF - C:\Program Files (x86)\Nitro\Pro 8\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: intel.com/AppUp - C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp.dll No File
FF Plugin HKCU: intel.com/AppUpx64 - C:\Program Files (x86)\Intel\IntelAppStore\bin\npAppUp_x64.dll No File
FF SearchPlugin: C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\u2cdbf3d.default\searchplugins\avira-safesearch.xml
FF SearchPlugin: C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\u2cdbf3d.default\searchplugins\search_engine.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\u2cdbf3d.default\Extensions\abs@avira.com [2014-04-14]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\coFFPlgn\ []
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\IPSFF [2014-01-11]
==================== Services (Whitelisted) =================
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-01-11] (Adobe Systems)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [152568 2013-02-28] (Lenovo Corporation)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [122448 2014-04-01] (Avira Operations GmbH & Co. KG)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2211000 2014-03-30] (Microsoft Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131032 2013-01-14] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-01-14] (Intel Corporation)
R2 Lenovo QuickSnip Service; C:\Program Files\lenovo\QuickSnipService\QuickSnipService.exe [219976 2013-06-05] (LENOVO INCORPORATED.)
R2 Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [1628664 2013-02-06] (Lenovo Group Limited)
R2 Lenovo System Agent Service; C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe [562504 2013-06-05] (LENOVO INCORPORATED.)
R3 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [677880 2013-02-28] (Lenovo Corporation)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-10] (Lenovo Group Limited)
R2 LnvHotSpotSvc; C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe [465912 2013-04-08] (Lenovo)
R2 LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [463352 2013-03-27] ()
S3 LSCWinService; C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe [1674720 2013-09-25] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-08-28] ()
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 NitroDriverReadSpool8; C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [230408 2013-03-25] (Nitro PDF Software)
R2 SMARTHelperService; C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe [538416 2013-11-22] (SMART Technologies)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22888 2013-09-17] ()
R2 ValBioService; C:\Program Files\Lenovo Fingerprint Reader\ValBioService.exe [22872 2013-10-28] (Validity Sensors, Inc.)
R2 valWBFPolicyService; C:\Windows\System32\valWBFPolicyService.exe [40848 2013-10-28] (Validity Sensors, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3378416 2013-08-28] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
S0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [37472 2013-02-14] (Advanced Micro Devices, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\BASHDefs\20140121.001\BHDrvx64.sys [1526488 2013-12-18] (Symantec Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [131968 2012-10-30] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1342848 2012-12-03] (Motorola Solutions, Inc.)
R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2014-01-10] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2014-01-10] (Symantec Corporation)
R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\IPSDefs\20140207.001\IDSvia64.sys [521944 2014-01-21] (Symantec Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-14] (Malwarebytes Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20140210.001\ENG64.SYS [126040 2014-01-25] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20140210.001\EX64.SYS [2099288 2014-01-25] (Symantec Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-10-08] (Intel Corporation)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [277648 2012-09-19] (Realtek Semiconductor Corp.)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8243272 2013-03-21] (Realtek Semiconductor Corp.)
R3 SMARTMouseFilterx64; C:\Windows\System32\drivers\SMARTMouseFilterx64.sys [10240 2013-11-04] (SMART Technologies)
R3 SMARTVHidMiniVistaAmd64; C:\Windows\System32\drivers\SMARTVHidMiniVistaAmd64.sys [9216 2013-11-04] (SMART Technologies)
S3 SMARTVTabletPCx64; C:\Windows\System32\drivers\SMARTVTabletPCx64.sys [22184 2013-11-04] (SMART Technologies ULC)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2013-07-09] (Synaptics Incorporated)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
S3 SWIX64; C:\Program Files (x86)\Lenovo\System Update\tvsuhd64.sys [33856 2012-09-12] (Lenovo Group Limited)
R3 SymDS; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R3 SymEFA; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
S4 SymELAM; C:\Windows\system32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-11-15] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [177312 2014-01-11] (Symantec Corporation)
R3 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2013-09-06] (Seiko Epson Corporation)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [48024 2013-01-28] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [194456 2013-01-28] (Windows (R) Win 7 DDK provider)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-21 23:52 - 2014-04-21 23:52 - 00000000 ____D () C:\FRST
2014-04-21 23:48 - 2014-04-21 23:52 - 00000000 ____D () C:\Users\Arne\Desktop\Trojanerboard
2014-04-21 21:55 - 2014-04-21 21:55 - 00000000 ____D () C:\ProgramData\Licenses
2014-04-21 21:53 - 2014-04-21 21:53 - 21407864 _____ (Simply Super Software ) C:\Users\Arne\Downloads\trjsetup690.exe
2014-04-15 23:17 - 2014-04-15 23:16 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2014-04-14 23:13 - 2014-04-14 23:13 - 00000085 _____ () C:\WINDOWS\wininit.ini
2014-04-14 22:48 - 2014-04-14 22:58 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-14 22:48 - 2014-04-14 22:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-14 22:47 - 2014-04-14 22:48 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Arne\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-14 22:44 - 2014-04-14 23:13 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-04-14 22:44 - 2014-04-14 23:13 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-04-14 22:44 - 2014-04-14 22:44 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking
2014-04-14 22:42 - 2014-04-14 22:43 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\Arne\Downloads\spybot-2.2.25.exe
2014-04-14 22:37 - 2014-04-14 22:39 - 00000000 ____D () C:\AdwCleaner
2014-04-14 22:37 - 2014-04-14 22:37 - 01426178 _____ () C:\Users\Arne\Downloads\adwcleaner3023.exe
2014-04-14 22:27 - 2014-04-14 22:27 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Avira
2014-04-14 22:22 - 2014-02-25 11:41 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2014-04-14 22:22 - 2014-02-25 11:41 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2014-04-14 22:22 - 2014-02-25 11:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2014-04-14 22:18 - 2014-04-14 22:21 - 00000000 ____D () C:\ProgramData\Avira
2014-04-14 22:18 - 2014-04-14 22:21 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-04-14 22:18 - 2014-04-14 22:18 - 04464256 _____ (Avira Operations GmbH & Co. KG) C:\Users\Arne\Downloads\avira_de_av___ws.exe
2014-04-14 22:18 - 2014-04-14 22:18 - 00001148 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-04-14 21:15 - 2014-01-27 05:42 - 02232664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2014-04-14 21:14 - 2014-03-07 02:48 - 01766400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-04-14 21:14 - 2014-03-07 02:48 - 01140736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-04-14 21:14 - 2014-03-07 02:47 - 14357504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-04-14 21:14 - 2014-03-07 02:47 - 13760512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-04-14 21:14 - 2014-03-07 02:47 - 02877952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-04-14 21:14 - 2014-03-07 02:47 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-04-14 21:14 - 2014-03-07 02:47 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-04-14 21:14 - 2014-03-07 02:47 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-04-14 21:14 - 2014-03-07 02:47 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 19273216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 15404544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 03959808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 02648576 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 02240000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-04-14 21:14 - 2014-03-07 02:08 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-04-14 21:14 - 2014-02-04 01:56 - 00332632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2014-04-14 21:14 - 2014-02-04 01:56 - 00278872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2014-04-14 21:14 - 2014-01-31 05:55 - 00209712 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationUI.exe
2014-04-14 21:14 - 2014-01-31 02:48 - 00564736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-04-14 21:14 - 2014-01-31 02:48 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2014-04-14 21:14 - 2014-01-31 02:48 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2014-04-14 21:14 - 2014-01-31 02:48 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-14 21:14 - 2014-01-31 02:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-04-14 21:14 - 2014-01-31 02:06 - 00599040 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2014-04-14 21:14 - 2014-01-31 02:06 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-14 21:14 - 2014-01-27 05:39 - 01939288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2014-04-14 21:14 - 2014-01-27 02:52 - 17561088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2014-04-14 21:14 - 2014-01-27 02:31 - 19752448 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2014-04-14 21:14 - 2014-01-27 01:17 - 00386722 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-04-14 21:14 - 2014-01-16 01:42 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2014-04-14 21:14 - 2014-01-11 08:48 - 05979648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-04-14 21:14 - 2014-01-11 07:06 - 05092352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-04-14 21:14 - 2014-01-03 01:35 - 00365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsGdiConverter.dll
2014-04-14 21:14 - 2014-01-03 01:32 - 00523264 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsGdiConverter.dll
2014-04-14 21:14 - 2013-05-16 00:37 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2014-04-14 21:14 - 2013-05-16 00:35 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-04-14 21:14 - 2013-05-14 15:14 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-04-14 21:14 - 2013-05-14 11:23 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-04-14 21:14 - 2013-02-21 12:29 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-04-14 21:14 - 2013-02-21 12:29 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-04-14 21:14 - 2013-02-21 12:29 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-04-14 21:14 - 2013-02-21 12:29 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-04-14 21:14 - 2013-02-21 12:14 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-04-14 21:14 - 2013-02-21 12:14 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-04-14 21:14 - 2013-02-19 11:53 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2014-04-14 21:14 - 2012-11-08 06:20 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-04-14 21:14 - 2012-11-08 06:20 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-04-14 21:14 - 2012-07-26 05:06 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-04-11 16:38 - 2014-04-11 16:49 - 09307744 _____ () C:\Users\Arne\Downloads\Wir Kinder aus Bullerbü.avi
2014-04-10 09:58 - 2014-04-10 09:59 - 00000000 ____D () C:\Users\Arne\Desktop\Transcend
2014-04-10 00:59 - 2014-04-10 00:59 - 00000000 ____D () C:\ProgramData\GridinSoft
2014-04-10 00:58 - 2014-04-10 00:59 - 46103912 _____ (GridinSoft LLC) C:\Users\Arne\Downloads\Gtk-2.2.2.4-setup.exe
2014-04-09 23:28 - 2014-04-10 23:01 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\dvdcss
2014-04-09 23:27 - 2014-04-14 22:33 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-04-09 23:27 - 2014-04-09 23:27 - 25531584 _____ () C:\Users\Arne\Downloads\vlc-2.1.3-win32.exe
2014-04-09 23:25 - 2014-04-09 23:25 - 00017237 _____ () C:\Users\Arne\Downloads\vlc-2.1.4-win64.exe
2014-04-09 01:24 - 2014-04-09 01:25 - 02600664 _____ (Visicom Media Inc.) C:\Users\Arne\Downloads\z_downloader.exe
2014-04-08 21:40 - 2014-02-06 01:41 - 01257984 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2014-04-08 21:40 - 2014-02-06 01:41 - 00978432 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2014-04-08 21:40 - 2014-02-06 01:26 - 00666112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2014-04-08 21:40 - 2014-02-06 01:19 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2014-04-08 01:30 - 2014-04-08 01:30 - 00025609 _____ () C:\Users\Arne\Downloads\stadtspiele_berlin_tour1_karte19.kml
2014-04-08 01:15 - 2014-04-08 01:15 - 00130048 _____ () C:\Users\Arne\Downloads\Bestellblatt.xls
2014-04-01 23:19 - 2014-04-01 23:19 - 00000000 _____ () C:\Users\Arne\Downloads\0B3PvZP6dXZEWUTRmSC03RkxLZjQ.htm
2014-04-01 21:00 - 2014-04-01 21:00 - 00000017 _____ () C:\Users\Arne\AppData\Local\resmon.resmoncfg
2014-04-01 03:36 - 2014-04-21 23:44 - 00000922 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-01 03:36 - 2014-04-21 22:41 - 00000926 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-01 03:36 - 2014-04-01 21:03 - 00000000 ____D () C:\Users\Arne\AppData\Local\Google
2014-04-01 03:36 - 2014-04-01 03:36 - 00884672 _____ (Google Inc.) C:\Users\Arne\Downloads\googledrivesync.exe
2014-04-01 03:36 - 2014-04-01 03:36 - 00003898 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-01 03:36 - 2014-04-01 03:36 - 00003662 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-01 03:36 - 2014-04-01 03:36 - 00000000 ____D () C:\Program Files (x86)\Google
2014-03-30 02:24 - 2014-03-30 02:24 - 00063488 _____ () C:\Users\Arne\Downloads\P-Konto_Haushaltsplan.xls
2014-03-29 22:06 - 2014-03-29 22:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 13:02 - 2014-03-27 13:04 - 22032853 _____ () C:\Users\Arne\Downloads\Klassenbilder 2013.pptx
2014-03-27 13:02 - 2014-03-27 13:04 - 15221023 _____ () C:\Users\Arne\Downloads\Klassenfotos 2012-13.pptx
2014-03-25 23:11 - 2014-03-25 23:11 - 00325144 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-24 22:08 - 2013-10-25 09:34 - 00035856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2014-03-24 22:08 - 2013-10-25 00:34 - 00248240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2014-03-23 22:36 - 2014-02-08 06:34 - 04036608 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-03-23 00:05 - 2014-02-06 01:41 - 00595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2014-03-23 00:05 - 2014-02-06 01:37 - 00496640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2014-03-23 00:05 - 2014-01-31 02:48 - 01339392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2014-03-23 00:05 - 2014-01-31 02:06 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
==================== One Month Modified Files and Folders =======
2014-04-21 23:52 - 2014-04-21 23:52 - 00000000 ____D () C:\FRST
2014-04-21 23:52 - 2014-04-21 23:48 - 00000000 ____D () C:\Users\Arne\Desktop\Trojanerboard
2014-04-21 23:49 - 2014-01-11 14:03 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3376538931-3444952228-2368489750-1001
2014-04-21 23:44 - 2014-04-01 03:36 - 00000922 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-21 23:44 - 2014-01-11 13:56 - 00000379 _____ () C:\Users\Arne\AppData\Local\RegisteredPackageInformation.xml
2014-04-21 23:02 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-04-21 23:00 - 2014-01-11 22:53 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-04-21 22:41 - 2014-04-01 03:36 - 00000926 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-21 22:20 - 2013-08-10 10:05 - 01422637 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-21 22:10 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2014-04-21 21:55 - 2014-04-21 21:55 - 00000000 ____D () C:\ProgramData\Licenses
2014-04-21 21:53 - 2014-04-21 21:53 - 21407864 _____ (Simply Super Software ) C:\Users\Arne\Downloads\trjsetup690.exe
2014-04-16 01:20 - 2014-02-10 11:41 - 00000000 ____D () C:\Users\Arne\Desktop\privat
2014-04-16 01:01 - 2013-08-10 19:58 - 00753134 _____ () C:\WINDOWS\system32\perfh007.dat
2014-04-16 01:01 - 2013-08-10 19:58 - 00155826 _____ () C:\WINDOWS\system32\perfc007.dat
2014-04-16 01:01 - 2012-07-26 09:28 - 01745416 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-04-16 00:59 - 2014-01-13 11:18 - 03121664 ___SH () C:\Users\Arne\Desktop\Thumbs.db
2014-04-15 23:41 - 2014-01-11 23:53 - 00000000 ____D () C:\Users\Arne\AppData\Local\Deployment
2014-04-15 23:16 - 2014-04-15 23:17 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2014-04-14 23:13 - 2014-04-14 23:13 - 00000085 _____ () C:\WINDOWS\wininit.ini
2014-04-14 23:13 - 2014-04-14 22:44 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-04-14 23:13 - 2014-04-14 22:44 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-04-14 23:00 - 2014-01-11 13:57 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Nitro PDF
2014-04-14 22:59 - 2014-01-19 21:31 - 00005160 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for Arne_Walther_PC-Arne Arne_Walther_PC
2014-04-14 22:58 - 2014-04-14 22:48 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-04-14 22:57 - 2013-03-25 23:02 - 00109964 _____ () C:\WINDOWS\PFRO.log
2014-04-14 22:57 - 2012-07-26 09:22 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-04-14 22:57 - 2012-07-26 07:26 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-04-14 22:48 - 2014-04-14 22:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-14 22:48 - 2014-04-14 22:47 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Arne\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-14 22:44 - 2014-04-14 22:44 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Safer-Networking
2014-04-14 22:43 - 2014-04-14 22:42 - 40658208 _____ (Safer-Networking Ltd. ) C:\Users\Arne\Downloads\spybot-2.2.25.exe
2014-04-14 22:41 - 2014-01-11 13:57 - 00000000 ___RD () C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-14 22:41 - 2014-01-11 13:57 - 00000000 ___RD () C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-14 22:39 - 2014-04-14 22:37 - 00000000 ____D () C:\AdwCleaner
2014-04-14 22:39 - 2012-07-26 10:12 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-04-14 22:39 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\WinStore
2014-04-14 22:37 - 2014-04-14 22:37 - 01426178 _____ () C:\Users\Arne\Downloads\adwcleaner3023.exe
2014-04-14 22:33 - 2014-04-09 23:27 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-04-14 22:27 - 2014-04-14 22:27 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Avira
2014-04-14 22:21 - 2014-04-14 22:18 - 00000000 ____D () C:\ProgramData\Avira
2014-04-14 22:21 - 2014-04-14 22:18 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-04-14 22:18 - 2014-04-14 22:18 - 04464256 _____ (Avira Operations GmbH & Co. KG) C:\Users\Arne\Downloads\avira_de_av___ws.exe
2014-04-14 22:18 - 2014-04-14 22:18 - 00001148 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-04-14 22:18 - 2013-08-10 10:13 - 00000000 ____D () C:\ProgramData\Package Cache
2014-04-14 21:13 - 2014-01-11 14:10 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-04-11 17:03 - 2014-01-16 21:26 - 00000000 ____D () C:\Users\Arne\Desktop\Bio_SEKI
2014-04-11 16:49 - 2014-04-11 16:38 - 09307744 _____ () C:\Users\Arne\Downloads\Wir Kinder aus Bullerbü.avi
2014-04-11 16:02 - 2013-08-10 10:21 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Lenovo
2014-04-11 16:02 - 2013-08-10 10:12 - 00000000 ____D () C:\Program Files\Lenovo
2014-04-10 23:01 - 2014-04-09 23:28 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\dvdcss
2014-04-10 10:02 - 2012-07-26 09:21 - 00032557 _____ () C:\WINDOWS\setupact.log
2014-04-10 10:00 - 2012-07-26 07:26 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-04-10 09:59 - 2014-04-10 09:58 - 00000000 ____D () C:\Users\Arne\Desktop\Transcend
2014-04-10 09:58 - 2014-01-11 14:19 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-10 09:36 - 2014-03-19 08:33 - 00000000 ____D () C:\Users\Arne\Desktop\Freischütz
2014-04-10 09:36 - 2014-01-16 21:26 - 00000000 ____D () C:\Users\Arne\Desktop\Geschichte_SEKI
2014-04-10 09:36 - 2014-01-16 21:26 - 00000000 ____D () C:\Users\Arne\Desktop\Bio_SEKII
2014-04-10 00:59 - 2014-04-10 00:59 - 00000000 ____D () C:\ProgramData\GridinSoft
2014-04-10 00:59 - 2014-04-10 00:58 - 46103912 _____ (GridinSoft LLC) C:\Users\Arne\Downloads\Gtk-2.2.2.4-setup.exe
2014-04-09 23:27 - 2014-04-09 23:27 - 25531584 _____ () C:\Users\Arne\Downloads\vlc-2.1.3-win32.exe
2014-04-09 23:25 - 2014-04-09 23:25 - 00017237 _____ () C:\Users\Arne\Downloads\vlc-2.1.4-win64.exe
2014-04-09 23:23 - 2014-01-11 13:56 - 00000000 ____D () C:\Users\Arne\AppData\Local\Packages
2014-04-09 18:27 - 2014-01-12 15:05 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-04-09 18:26 - 2014-01-12 15:05 - 90655440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-04-09 17:06 - 2014-01-25 00:30 - 00000344 _____ () C:\WINDOWS\lgfwup.ini
2014-04-09 17:06 - 2014-01-25 00:30 - 00000000 ____D () C:\Program Files (x86)\lg_fwupdate
2014-04-09 16:39 - 2014-01-11 14:33 - 00000000 ____D () C:\Users\Arne\AppData\Local\Adobe
2014-04-09 16:17 - 2014-01-11 22:53 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-04-09 01:25 - 2014-04-09 01:24 - 02600664 _____ (Visicom Media Inc.) C:\Users\Arne\Downloads\z_downloader.exe
2014-04-08 01:30 - 2014-04-08 01:30 - 00025609 _____ () C:\Users\Arne\Downloads\stadtspiele_berlin_tour1_karte19.kml
2014-04-08 01:15 - 2014-04-08 01:15 - 00130048 _____ () C:\Users\Arne\Downloads\Bestellblatt.xls
2014-04-01 23:19 - 2014-04-01 23:19 - 00000000 _____ () C:\Users\Arne\Downloads\0B3PvZP6dXZEWUTRmSC03RkxLZjQ.htm
2014-04-01 21:03 - 2014-04-01 03:36 - 00000000 ____D () C:\Users\Arne\AppData\Local\Google
2014-04-01 21:00 - 2014-04-01 21:00 - 00000017 _____ () C:\Users\Arne\AppData\Local\resmon.resmoncfg
2014-04-01 03:36 - 2014-04-01 03:36 - 00884672 _____ (Google Inc.) C:\Users\Arne\Downloads\googledrivesync.exe
2014-04-01 03:36 - 2014-04-01 03:36 - 00003898 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-01 03:36 - 2014-04-01 03:36 - 00003662 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-01 03:36 - 2014-04-01 03:36 - 00000000 ____D () C:\Program Files (x86)\Google
2014-03-31 23:18 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-03-31 23:18 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-30 02:24 - 2014-03-30 02:24 - 00063488 _____ () C:\Users\Arne\Downloads\P-Konto_Haushaltsplan.xls
2014-03-29 22:06 - 2014-03-29 22:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 13:04 - 2014-03-27 13:02 - 22032853 _____ () C:\Users\Arne\Downloads\Klassenbilder 2013.pptx
2014-03-27 13:04 - 2014-03-27 13:02 - 15221023 _____ () C:\Users\Arne\Downloads\Klassenfotos 2012-13.pptx
2014-03-27 01:07 - 2014-01-25 00:23 - 00000000 ____D () C:\ProgramData\CyberLink
2014-03-27 01:05 - 2014-01-27 22:45 - 00000000 ____D () C:\Users\Public\CyberLink
2014-03-25 23:11 - 2014-03-25 23:11 - 00325144 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-03-25 23:10 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-25 23:10 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-03-25 23:10 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-25 23:10 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
Some content of TEMP:
====================
C:\Users\Arne\AppData\Local\Temp\avgnt.exe
C:\Users\Arne\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-21 23:11
==================== End Of Log ============================ --- --- ---
und die addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-04-2014 02
Ran by Arne at 2014-04-21 23:52:53
Running from C:\Users\Arne\Desktop\Trojanerboard
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Norton Internet Security (Disabled - Out of date) {63DF5164-9100-186D-2187-8DC619EFD8BF}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Disabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: Norton Internet Security (Disabled - Out of date) {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security (Disabled) {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
==================== Installed Programs ======================
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 4.0.0.1390 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 4.0.0.1390 - Adobe Systems Incorporated) Hidden
Adobe Bridge 1.0 (x32 Version: 001.000.001 - Adobe Systems) Hidden
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.182 - Adobe Systems Incorporated)
Adobe Help Center 1.0 (x32 Version: 1.0.1 - Adobe Systems) Hidden
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0407-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Adobe Photoshop CS2 (x32 Version: 9.0 - Adobe Systems, Inc.) Hidden
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Adobe Stock Photos 1.0 (x32 Version: 1.0.1 - Adobe Systems) Hidden
AMD Accelerated Video Transcoding (Version: 12.10.100.30307 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{9AFDDE41-F96B-640E-E590-F31A52E205C1}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Anzeige am Bildschirm (HKLM\...\OnScreenDisplay) (Version: 7.11.50 - )
AudibleManager (HKLM-x32\...\AudibleManager) (Version: 18414980.4759644.48.2001811272 - Audible, Inc.)
Avira (HKLM-x32\...\{a9aa166b-f5d7-419f-92fc-c0c86c93ca53}) (Version: 1.0.5204.23256 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.0.5204.23256 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center (x32 Version: 2013.0307.2216.39940 - Ihr Firmenname) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2013.0307.2216.39940 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2013.0307.2216.39940 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2013.0307.2216.39940 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Profiles Mobile (x32 Version: 2013.0307.2216.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Standard (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Chinese Traditional (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Czech (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Danish (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Dutch (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help English (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Finnish (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help French (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help German (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Greek (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Hungarian (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Italian (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Japanese (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Korean (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Norwegian (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Polish (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Portuguese (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Russian (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Spanish (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Swedish (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Thai (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
CCC Help Turkish (x32 Version: 2013.0307.2215.39940 - Advanced Micro Devices, Inc.) Hidden
ccc-utility64 (Version: 2013.0307.2216.39940 - Advanced Micro Devices, Inc.) Hidden
CyberLink LabelPrint 2.5 (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5220 - CyberLink Corp.)
CyberLink LabelPrint 2.5 (x32 Version: 2.5.5220 - CyberLink Corp.) Hidden
CyberLink Media Suite 8 (HKLM-x32\...\InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}) (Version: 8.0.2820b - CyberLink Corp.)
CyberLink Media Suite 8 (x32 Version: 8.0.2820b - CyberLink Corp.) Hidden
CyberLink Power2Go 7 (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.2719b - CyberLink Corp.)
CyberLink Power2Go 7 (x32 Version: 7.0.0.2719b - CyberLink Corp.) Hidden
CyberLink PowerBackup 2.5 (HKLM-x32\...\{ADD5DB49-72CF-11D8-9D75-000129760D75}) (Version: 2.5.9102 - CyberLink Corp.)
CyberLink YouCam 3.1 (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.1.5324 - CyberLink Corp.)
CyberLink YouCam 3.1 (x32 Version: 3.1.5324 - CyberLink Corp.) Hidden
Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.8000.17 - Dolby Laboratories Inc)
EpsonNet Config V4 (HKLM-x32\...\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.4.1 - SEIKO EPSON CORPORATION)
EpsonNet SetupManager V2 (HKLM-x32\...\InstallShield_{485863E4-C20E-4629-A3B1-B4C8E706A7CB}) (Version: 2.1.4 - SEIKO EPSON CORPORATION)
EpsonNet SetupManager V2 (x32 Version: 2.1.4 - SEIKO EPSON CORPORATION) Hidden
Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden
Integrated Camera (HKLM-x32\...\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10224 - Realtek Semiconductor Corp.)
Intel AppUp(R) center (HKLM-x32\...\Intel AppUp(R) center 41900) (Version: 3.8.0.41900.72 - Intel)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3097 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation)
Intel(R) PRO/Wireless Driver (Version: 16.01.5000.0577 - Intel Corporation) Hidden
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 16.1.1.0084 - Intel Corporation) Hidden
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{DA2600C1-6BDF-4FD1-1212-148929CC1385}) (Version: 2.6.1212.0302 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) Update Manager (x32 Version: 1.5.0.87 - Intel Corporation) Hidden
Intel(R) WiDi (HKLM\...\{62E7C369-64FF-452C-8F46-6BE9B77FF097}) (Version: 4.0.18.0 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
Intel® PROSet/Wireless WiFi Software (Version: 16.01.5000.0269 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (Version: 1.27.757.1 - Intel Corporation) Hidden
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan)
Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217051FF}) (Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Lenovo Auto Scroll Utility (HKLM\...\LenovoAutoScrollUtility) (Version: 2.00 - )
Lenovo Dependency Package (HKLM-x32\...\Lenovo Dependency Package_is1) (Version: 1.5.37.0 - Lenovo Group Limited)
Lenovo Fingerprint Manager (HKLM\...\{26821A01-AE55-4B1A-807A-6EF888C4ACC2}) (Version: 4.5.240.0 - Validity Sensors, Inc.)
Lenovo Fingerprint Manager (HKLM\...\{F7AB2C19-6A27-4C75-A92A-8CC7C59E5FA2}) (Version: 4.5.240.0 - )
Lenovo Patch Utility (HKLM-x32\...\{AD32F5E9-6BDD-480A-8B7B-95571D04691C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.66.00.22 - )
Lenovo Settings - Camera Audio (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 4.0.96.0 - Lenovo Corporation)
Lenovo Settings Dependency Package (HKLM\...\{3694BA2E-BE31-4B7E-886B-A0B559E69D4D}_is1) (Version: 1.1.1.9 - Lenovo Group Limited)
Lenovo Settings Mobile Hotspot (HKLM\...\{42603F7D-B08D-436B-B0D8-3E2DEF1AFD41}_is1) (Version: 1.1.0.56 - Lenovo)
Lenovo Solution Center (HKLM\...\{D60E3A84-5DDC-49ED-B9A5-E3466996EB36}) (Version: 2.3.002.00 - Lenovo Group Limited)
Lenovo System Update (HKLM-x32\...\{25C64847-B900-48AD-A164-1B4F9B774650}) (Version: 5.03.0005 - Lenovo)
Lenovo User Guide (HKLM-x32\...\{13F59938-C595-479C-B479-F171AB9AF64F}) (Version: 1.0.0012.00 - Lenovo Group Limited)
Lenovo Warranty Information (HKLM-x32\...\{FD4EC278-C1B1-4496-99ED-C0BE1B0AA521}) (Version: 1.0.0011.00 - Lenovo)
LG ODD Auto Firmware Update (HKLM-x32\...\{6179550A-3E7C-499E-BCC9-9E8113E0A285}) (Version: 10.01.0712.01 - )
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.8.141.11 - McAfee, Inc.)
Microsoft Office Home and Student 2013 - de-de (HKLM\...\HomeStudentRetail - de-de) (Version: 15.0.4605.1003 - Microsoft Corporation)
Microsoft SkyDrive (HKCU\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.31117 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (Version: 10.0.31121 - Microsoft Corporation) Hidden
Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
Natura Simulationen Oekologie (HKLM-x32\...\{F40ECD46-5D2D-441D-9C76-780E7F6E4002}) (Version: 1.00.0000 - Ernst Klett Verlag)
Nitro Pro 8 (HKLM\...\{35E1FF5F-E8E1-4DE2-B3EC-BBE296B27336}) (Version: 8.5.2.10 - Nitro)
Norton Internet Security (HKLM-x32\...\NIS) (Version: 20.4.0.40 - Symantec Corporation)
OEM Application Profile (HKLM-x32\...\{C89A97B6-F991-EBB5-77B7-927BCF420EBE}) (Version: 1.00.0000 - Ihr Firmenname)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4605.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4605.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4605.1003 - Microsoft Corporation) Hidden
PowerXpressHybrid (x32 Version: 1.00.0000 - Ihr Firmenname) Hidden
PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.10.1226.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6870 - Realtek Semiconductor Corp.)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.9200.29040 - Realtek Semiconductor Corp.)
SMART Common Files (HKLM-x32\...\{26A95DBF-A866-4838-A8C9-FA219FCBD22E}) (Version: 11.5.159.0 - SMART Technologies ULC)
SMART German Language Pack (HKLM-x32\...\{8F98EED9-2AB7-4B92-B37F-70C6877C1783}) (Version: 11.4.19.0 - SMART Technologies ULC)
SMART Ink (HKLM-x32\...\{5ABC49B5-D0DC-428D-A082-4AEFF6490F04}) (Version: 2.0.721.0 - SMART Technologies ULC)
SMART Notebook (HKLM-x32\...\{79660EE7-9C0B-4962-B566-2693FE34719D}) (Version: 11.4.564.0 - SMART Technologies ULC)
SMART Produkttreiber (HKLM-x32\...\{53330A17-78DE-458E-9997-292A2D6D3ADD}) (Version: 11.4.479.0 - SMART Technologies ULC)
SugarSync Manager (HKLM-x32\...\SugarSync) (Version: 1.9.80.99066 - SugarSync, Inc.)
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 16.6.4.27 - )
ThinkVantage System für aktiven Festplattenschutz (HKLM\...\{46A84694-59EC-48F0-964C-7E76E9F8A2ED}) (Version: 1.77.0.11 - Lenovo)
Windows-Treiberpaket - Intel Corporation (iaStorA) HDC (11/19/2012 11.7.0.1013) (HKLM\...\D1AAAA88A17BD0C40261ADD70E15166BF4D1C076) (Version: 11/19/2012 11.7.0.1013 - Intel Corporation)
Windows-Treiberpaket - Lenovo 1.66.00.22 (11/30/2012 1.66.00.22) (HKLM\...\16E722986C4293F5D6BF43595DFFD631398D5F21) (Version: 11/30/2012 1.66.00.22 - Lenovo)
==================== Restore Points =========================
23-03-2014 20:49:56 Windows Update
01-04-2014 19:03:06 Removed Google Drive
08-04-2014 21:03:18 Windows Update
14-04-2014 19:46:01 Windows Update
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {001AB9A6-FFDE-4E92-AB4C-97FB1FA7572F} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program => C:\Program Files\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2013-09-25] (Lenovo)
Task: {009C45E3-6368-4E42-B698-4F48BE625D0F} - System32\Tasks\Lenovo\LenovoDependencyVersionTask => C:\Program Files\lenovo\SystemAgent\DependencyVersion.exe [2013-06-05] ()
Task: {026D123E-0AAA-43F6-BE26-4DEBAFE4D5D1} - \FoxTab No Task File <==== ATTENTION
Task: {03F77302-AD40-4770-A8C3-AFEC76CFD050} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-01] (Google Inc.)
Task: {06389DE1-0CFE-450F-B34C-B805F15F0EB7} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-09-25] ()
Task: {157986FB-8BEE-4D25-B3D8-EECBD4398355} - System32\Tasks\Dolby Selector => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [2012-08-31] (Dolby Laboratories Inc.)
Task: {15DE343A-FC21-4936-B083-B673DF556A09} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation)
Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {1DFF5362-16F9-42F9-A803-1BB0018339A4} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation)
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {2AFAE3EF-27A1-4E00-9537-33F145E78728} - System32\Tasks\TVT\TVSUUpdateTask => C:\Program Files (x86)\Lenovo\System Update\tvsuShim.exe [2013-09-17] ()
Task: {3CD0727A-1628-45E0-BC0A-FFB8251ECF30} - System32\Tasks\Lenovo\LenovoWarrantyChinaTask => C:\Program Files\lenovo\SystemAgent\ChinaWarrantyService.exe [2013-06-05] ()
Task: {463D939D-2E88-4037-B501-79DD43132B79} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-09] (Adobe Systems Incorporated)
Task: {5124E97B-8C2D-4D8A-899C-F11F19EFFB58} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-01] (Google Inc.)
Task: {53853A5A-94CA-4235-8900-A3441175F196} - System32\Tasks\Lenovo\LSC\LSCHardwareScanPostpone => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2013-09-25] ()
Task: {6318CB26-FF3C-428C-B0A2-DB6D6BB37788} - System32\Tasks\Dolby => c:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [2012-08-31] (Dolby Laboratories Inc.)
Task: {6B6AC68D-812F-431E-A1B8-71928F4AC947} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-03-08] (Realtek Semiconductor)
Task: {6DE21DF3-EE6F-405D-81A1-D795E0E81171} - System32\Tasks\Microsoft\Windows\Setup\Windows Upgrade Notification Task => C:\WINDOWS\system32\NotificationUI.exe [2014-01-31] (Microsoft Corporation)
Task: {818B5495-7DAB-409F-90E4-A48471730772} - System32\Tasks\Lenovo\LenovoMachineInformation => C:\Program Files\lenovo\SystemAgent\MachineInformation.exe [2013-06-05] ()
Task: {975ED6B6-75D8-4AED-A107-023F17DD2B22} - System32\Tasks\Lenovo\LenovoUserguidesCopy => C:\Program Files\lenovo\SystemAgent\UserguidesCopy.exe [2013-06-05] ()
Task: {A5619970-5D36-4503-8D63-AB1D8BA22547} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2013-09-25] (Lenovo)
Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {AC7FFFB4-BD1E-45E1-885C-B56C3FF236FB} - System32\Tasks\Intel\Intel Service Manager => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
Task: {AC93EC8F-FE0A-47A4-8B19-95FC723647E6} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => Rundll32.exe C:\WINDOWS\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)"
Task: {AD9A2816-E818-42CD-B64B-24236194A2B7} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {B440739E-AF8E-43A4-962A-3B1AE423033A} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Arne_Walther_PC-Arne Arne_Walther_PC => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2014-04-14] (Microsoft Corporation)
Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {C9879259-FE0C-4AD7-B3FF-DB8D3D0A7A16} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation)
Task: {CEFCEEC4-C7E9-415C-9AFC-A751FB8AEA39} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-06-14] (CyberLink)
Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {EC361950-D4EA-4517-840C-A644AE3B9791} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-03-26] (Realtek Semiconductor)
Task: {EDD9743F-B287-44D5-BB5C-0EA77431DFBD} - System32\Tasks\ISM-UpdateService-e57b59e7-5862-4250-9ce0-76fb411dc0d2 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\Bootstrap.exe [2012-11-23] (Intel Corporation)
Task: {F7B47C14-72CB-4E90-9BB6-7B4C0008EB1B} - System32\Tasks\ISM-UpdateService-e57b59e7-5862-4250-9ce0-76fb411dc0d2-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\Bootstrap.exe [2012-11-23] (Intel Corporation)
Task: {FA737A41-4740-4FF0-A377-CA6D79696677} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-03-30] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-08-10 10:24 - 2013-03-21 07:31 - 00115712 ____N () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL
2014-03-19 09:47 - 2013-10-31 18:13 - 00102568 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2014-01-11 14:10 - 2014-03-25 13:21 - 00629928 _____ () C:\Program Files\Microsoft Office 15\ClientX64\StreamServer.dll
2014-03-05 16:19 - 2014-03-05 16:19 - 00787456 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\Windows.Networking\543e76ed6aca1b57287f8e67db0677fb\Windows.Networking.ni.dll
2013-03-27 13:37 - 2013-03-27 13:37 - 00463352 _____ () C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
2013-03-27 13:36 - 2013-03-27 13:36 - 00014328 _____ () C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
2013-08-10 10:10 - 2013-03-01 20:45 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2014-04-14 22:22 - 2014-02-25 11:41 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-04-01 13:57 - 2014-04-01 13:57 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-04-01 13:57 - 2014-04-01 13:57 - 00064592 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2014-03-24 22:20 - 2014-03-24 22:20 - 00491008 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Networking\802024e2439ee2d55a3d6bc065088cb1\Windows.Networking.ni.dll
2014-03-24 22:20 - 2014-03-24 22:20 - 00184832 _____ () C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Windows.Foundation\1141dab55e0fcf5212915fdbe88af8ac\Windows.Foundation.ni.dll
2013-08-10 10:10 - 2013-01-14 20:25 - 01200088 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
2013-08-10 10:24 - 2013-02-28 14:35 - 02201088 _____ () C:\Program Files\Lenovo\Communications Utility\cxcore210.dll
2013-08-10 10:24 - 2013-02-28 14:35 - 02085888 _____ () C:\Program Files\Lenovo\Communications Utility\cv210.dll
2014-01-11 21:45 - 2012-05-30 08:51 - 00699280 ____R () C:\PROGRAM FILES (X86)\NORTON INTERNET SECURITY\ENGINE\20.4.0.40\wincfi39.dll
2013-08-22 20:43 - 2013-08-22 20:43 - 00272688 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\SBSDK.node
2013-08-22 20:44 - 2013-08-22 20:44 - 00039216 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\HWR.node
2013-08-22 20:44 - 2013-08-22 20:44 - 00053040 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\SWR.node
2013-08-22 20:44 - 2013-08-22 20:44 - 00057648 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\MWR.node
2013-08-22 20:44 - 2013-08-22 20:44 - 00014848 _____ () C:\Program Files (x86)\SMART Technologies\Education Software\sbsdk-server\node_modules\SessionNotification.node
2011-03-09 15:21 - 2011-03-09 15:21 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2011-03-09 15:21 - 2011-03-09 15:21 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2014-04-14 22:22 - 2014-04-01 13:57 - 00049744 _____ () C:\Users\Arne\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2014-03-29 22:06 - 2014-03-29 22:06 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: SMART Virtual TabletPC
Description: SMART Virtual TabletPC
Class Guid: {745a17a0-74d3-11d0-b6fe-00a0c90f57da}
Manufacturer: SMART Technologies ULC
Service: SMARTVTabletPCx64
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/15/2014 11:49:45 PM) (Source: Application Hang) (User: )
Description: Programm AcroRd32.exe, Version 11.0.6.70 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1f08
Startzeit: 01cf58f47690d4d6
Endzeit: 15
Anwendungspfad: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
Berichts-ID: d7caa916-c4e7-11e3-be82-606c66a14810
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/15/2014 11:16:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Arne_Walther_PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/15/2014 11:16:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Arne_Walther_PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/15/2014 11:16:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Arne_Walther_PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/15/2014 11:16:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Arne_Walther_PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/05/2014 00:16:01 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: Arne_Walther_PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/05/2014 00:16:01 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: Arne_Walther_PC)
Description: Bei der Aktivierung der App „microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (04/05/2014 00:16:01 AM) (Source: Microsoft-Windows-Immersive-Shell) (User: Arne_Walther_PC)
Description: Bei der Aktivierung der App „SymantecCorporation.NortonStudio_v68kp9n051hdp!App“ ist folgender Fehler aufgetreten: -2147467263. Weitere Informationen finden Sie im Protokoll „Microsoft-Windows-TWinUI/Betriebsbereit“.
Error: (03/25/2014 05:55:00 PM) (Source: Application Hang) (User: )
Description: Programm wwahost.exe, Version 6.2.9200.16420 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1c4c
Startzeit: 01cf483d881f7324
Endzeit: 4294967295
Anwendungspfad: C:\WINDOWS\system32\wwahost.exe
Berichts-ID: d054dc69-b435-11e3-be7e-606c66a14810
Vollständiger Name des fehlerhaften Pakets: microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Microsoft.WindowsLive.Mail
Error: (03/25/2014 05:54:58 PM) (Source: Microsoft-Windows-Immersive-Shell) (User: Arne_Walther_PC)
Description: Das Paket „microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe“ wurde beendet, da das Anhalten zu lange dauerte.
System errors:
=============
Error: (04/21/2014 10:09:37 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/21/2014 10:09:37 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/15/2014 11:16:08 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/15/2014 11:16:08 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/14/2014 10:57:55 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/14/2014 10:57:55 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/14/2014 10:57:51 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/14/2014 10:57:51 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/14/2014 10:40:29 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Error: (04/14/2014 10:40:29 PM) (Source: DCOM) (User: NT-AUTORITÄT)
Description: ComputerstandardLokalAktivierung{7160A13D-73DA-4CEA-95B9-37356478588A}Nicht verfügbarNT-AUTORITÄTLokaler DienstS-1-5-19LocalHost (unter Verwendung von LRPC)Nicht verfügbarNicht verfügbar
Microsoft Office Sessions:
=========================
Error: (04/15/2014 11:49:45 PM) (Source: Application Hang)(User: )
Description: AcroRd32.exe11.0.6.701f0801cf58f47690d4d615C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exed7caa916-c4e7-11e3-be82-606c66a14810
Error: (04/15/2014 11:16:13 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Arne_Walther_PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2147467263
Error: (04/15/2014 11:16:13 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Arne_Walther_PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2147467263
Error: (04/15/2014 11:16:13 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Arne_Walther_PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2147467263
Error: (04/15/2014 11:16:13 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Arne_Walther_PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2147467263
Error: (04/05/2014 00:16:01 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: Arne_Walther_PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2147467263
Error: (04/05/2014 00:16:01 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: Arne_Walther_PC)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!Microsoft.WindowsLive.Mail-2147467263
Error: (04/05/2014 00:16:01 AM) (Source: Microsoft-Windows-Immersive-Shell)(User: Arne_Walther_PC)
Description: SymantecCorporation.NortonStudio_v68kp9n051hdp!App-2147467263
Error: (03/25/2014 05:55:00 PM) (Source: Application Hang)(User: )
Description: wwahost.exe6.2.9200.164201c4c01cf483d881f73244294967295C:\WINDOWS\system32\wwahost.exed054dc69-b435-11e3-be7e-606c66a14810microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbweMicrosoft.WindowsLive.Mail
Error: (03/25/2014 05:54:58 PM) (Source: Microsoft-Windows-Immersive-Shell)(User: Arne_Walther_PC)
Description: microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe
CodeIntegrity Errors:
===================================
Date: 2014-03-03 11:25:16.666
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:25:15.582
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:25:14.482
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:25:13.413
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:23:58.819
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:23:57.734
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:23:56.646
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:23:55.552
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:22:02.446
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
Date: 2014-03-03 11:22:01.343
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Percentage of memory in use: 26%
Total physical RAM: 10073.66 MB
Available physical RAM: 7402.74 MB
Total Pagefile: 11545.66 MB
Available Pagefile: 8571 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:224.3 GB) (Free:168.89 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 238 GB) (Disk ID: 69677AFB)
Partition: GPT Partition Type.
==================== End Of Log ============================ Hoffe das war jetzt alles richtig wie ich es gemacht habe...
lg, Helianthus |